C2PA Cameras Do Not Survive Contact with Reality
da.vidbuchanan.co.uk
da.vidbuchanan.co.uk
You will not build a perfect system, or even something near perfect. The best you're going to do is make it so that it's hard to casually present AI photos as real, leaving only the cases where it really matters. In the "best" case, you've just made the public more trusting of photos in general, so that when there's actual money or power on the line that makes jumping through the hoops to fake authenticity worth it, the public is more susceptible.
The best outcome at this point is for everyone to get on the same page that photos have roughly the same probative value now as drawings. Poorly thought out snake oil efforts to prove authenticity are only going to delay that.
This is ridiculous.
How?
Right now, the Internet training set is becoming more and more contaminated with better and better generative AI images and video.
It makes the models more screwed up, and makes it very difficult for humans to figure out what is original and not too.
If there was some signal that could at least make it easier to identify ‘original’/real images…
The original model collapse paper assumes you train networks on 100% synthetic data produced by the previous generation. But if you maintain some portion of real data then the problem is mitigated.
I remember the original paper showing issues with even a couple percent of certain kinds of synthetic data too, not 100%.
People are concerned that the technology will lend additional credence to the last 0.1%. But anyone who thinks about the technology for 2 minutes will see you can just point the camera at the screen. In cases where it really matters (a court of law, internet arguments between nerds) people will know it's not 100% reliable. Locks can be picked, and signatures can be forged, but that doesn't make them useless.
"C2PA Cameras Do Not Survive Contact With Reality" does not survive contact with reality where very, very few users would even think of rooting their phone so they can create signed fake images.
Malicious users don't need to root their own phones. They just need to go to fakemyimage dot com, and someone else's rooted phone in a clickfarm-type setup signs it for them. I am not operating such a service myself because I thought it was unnecessary in making my point, but perhaps I will have to reconsider.
When a motivated malicious user (who doesn't actually need that much resources) will be able to convince people something is authentic because the verification passes when it shouldn't since naive users are primed to believe it by default.
Should we also abolish Pangram, because it's not 100% accurate? Someone might be convinced a text is not AI-generated when it actually is! We should get rid of it rather than fool people into thinking it can be determined accurately. What about antivirus? We should abolish it as well rather than fool people into thinking that their software is ever 100% safe. What about HTTPS? We shouldn't call it "secure" shell because the computer you're connecting to could be compromised! I could go on and on and on.
The median instance of AI image generation isn't evidence in a court case. It's cyberbullying, or deepfakes, or fake news. It's called "slop" because there's a lot of it being churned out at low effort.
While it is always an individual tragedy when people treat each other badly (e.g. through deepfakes and all), the real threat does not exist on that level.
This is about misinformation and disinformation, so we're talking state actors. And with that, the 99.9% hypothesis does not hold true.
I like being contrarian as much as the next guy, but "Actually, having security is worse for security" is taking it a little too far.
It is however in the interest of the people to keep the systems running in an untainted way.
As said, on the individual level it's a tragedy, but one that can be absorbed somewhat. Democracy itself failing otoh is kinda hard to absorb.
C2PA is not "having security". It is "having an illusion of security for compliance and CYA reasons, that can be fairly trivially exploited by nation state actors". Banality of evil. Again.
___
Actually, come to think of it, "security" is the wrong term there. Signatures don't secure anything. They attest.
Those are different things. Argh and I ran with your term aah
Not to mention, democracy is under just as much or more threat from "banal" fake news created by citizens. People gonna people. They don't need the DPRK lying to them to fool themselves.
And I agree on state actors. If a major one is invested in something like this they might have well compromised the signing project itself, the verification process, or even the court system or media. That seems like a rare and extremely high bar to guard against.
Yes, absolutely. Probably moreso. The whole point of these proposals is to try to solve for the "motivated malicious user" who is engaging in actual high-stakes fraud. There is no point in applying techniques that suppress inconsequential pranks while making serious crimes easier to get away with.
This really seems like a rehash of the perennial DRM argument: DRM restrictions provably do not reduce large-scale motivated copyright infringement, they just annoy legitimate paying users. This is the same class of solution, in that it is effective only where the stakes are low and the impact is minimal.
Also I'd like to know if a "joke" is likely fake.
Bur I don't even really think that's really relevant anyway, because whatever the density of "malicious" motivations is, the point here is that the fact that it only is an effort/motivation threshold that allows this technique to "block" malicious uses, and the motivation to overcome that threshold correlates directly with the stakes involved in the malicious use.
In other words, the more malicious the abuse is, the less effective this solution will be: the boundary of its usefulness will be wherever the line between pranksters and actual criminals happens to lie.
Your argument applies to any imperfect security technology -- aka practically all of them.
No, my idea of a criminal is someone who is motivated to commit crime, and I feel that we've already established in this thread that the approaches we're discussing are motivation gates far more than competence gates.
> Smart, dedicated, technical people can typically make more money legally.
Then who's been running all the botnets, writing cryptolocker malware, and running phishing scams for the past couple of decades?
We've always had script kiddies, and now we have people using AI itself to do malicious things. Technical skill has never been an obstacle for sufficiently motivated scammers.
> Your argument applies to any imperfect security technology -- aka practically all of them.
Ultimately, everything has weaknesses, and with enough effort, most measures can be circumvented. But how much effort is enough varies wildly between solutions.
There's a huge gulf between a "no trespassing" sign, on the one hand, and a concrete wall topped with barbed wire, on the other. The "no trespassing" sign only keeps out people willing to obey it; the concrete wall keeps out anyone who isn't willing and able to accept the time, effort, and risk necessary to climb over it or knock it down.
And the point is that using digital signatures to distinguish AI-generated media from hand-made media is much closer to the "no trespassing" side of things than it is to the wall. Maybe it's analogous to a gate with a latch you can open from the other side if you reach over in just the right spot.
And in this case we can clearly see that a solution that (a) does not substantially increase their costs -- and in fact, as I've pointed out above, only really filters by motivation, not by time, money or effort, and (b) doesn't target their potential benefits at all, is one that isn't likely to be effective.
* Pangram: Yes we should really be discouraging people from putting trust in tools like this because they can't be made totally reliable.
* Antivirus: We should be building application environments with robust security models so that malicious software has a limited blast radius (like we do on mobile, like the Linux ecosystem is trying to do with Flatpak, etc).
* HTTPS: HTTPS is a strict upgrade from HTTP so we should be using it everywhere possible. The UI symbols to indicate to users the security expectations they're getting are good practice.
* ssh: This is just an inappropriate comparison.
The HTTPS comparison would make more sense if actually 0.1% of the time when their browser said they were using HTTPS it was just lying.
Antivirus: "Actually, we should build this hypothetical better thing" is a cop-out.
HTTPS: C2PA is a strict upgrade from unsigned photographs, so it should be used wherever possible.
SSH: Totally appropriate, the entire point of the discussion is whether it's permissible to the user that they might be more secure.
Also, note that C2PA should have something like Level 3 as well: "The image is mathematically proven to have come from the physical camera sensor."
It's somehow difficult to achieve this, but it's possible (although the attacks will always be possible of course).
But yeah, difficult too :)
The screen is doing all kinds of crazy things that are not apparent to your eyes, but that show up clearly on camera.
For example, you'll see a sort of barber-pole effect when pointing a video camera at a raster-scan digital display whose refresh rate isn't synced to the camera's frame rate. To avoid that, sync them, or maybe use a colour e-ink display.
Alternatively, print a high-resolution version with a decent photograph printer and take a picture of the print with the C2PA camera.
Exactly: most people don't bother editing visible watermarks out of AI-generated media, because they have little or no incentive to bother doing so. This will "defeat" the 99.9% of users who are not actually trying to do anything malicious, but will be a minor annoyance to the 0.1% of users who are actively engaging in fraud, fabrication of evidence, etc.
The upshot is that not only us this not useful for its intended purpose, it will lure people into a false sense of security by creating expectations that AI-generated media will always be easily identifiable as such, and reduce the level of scrutiny that gets applied to the stuff that actually is malicious.
Everyone realizing that photos don't prove anything would defeat 100% of malicious users. I don't understand what people incorrectly trusting photos is supposed to achieve at this point, in your view.
Make it a legal requirement to mark AI generated photos and enforce penalties for posting unmarked AI generations. Social media should also mark the country of origin for each post, with the knowledge that posts from your own country are covered by these laws.
The point is making it easier to go after bot accounts that spam generated videos to influence politics. They need to disclose that its AI and lose their power or lie and get criminally prosecuted.
It's not the same thing as model providers adding a mandatory watermark to everything, and even worse one you can't verify yourself and have to trust that Anthropic is telling everyone the truth. People should have the option to use undetectable AI tools in private, even if it's illegal to post the outputs on social media.
I say "nearly", because as soon as you need to keep a private key secure from someone with direct physical access to the device, you're entering dangerous territory. TTBOMK there's no way to make a "perfect black box", so it becomes an arms race between defensive "obfuscation" and tamper detection mechanisms in the one hand and stealth scanning techniques on the other. But this is already the case for TPMs -- that is, the situation is no worse than for an already widely accepted technology.
Really, everyone should know by now it is not as simple as that. We already have lots of laws that are not enforced (fully or at all) because there is a cost to enforcing the law - time and money. Some random person uploads an AI image to Facebook and you really expect the police to expend a few thousand $ prosecuting them for what? To Server as a warning?
Some people will be untraceable. Some will claim innocence or mitigation or some disability that excuses them. Even those that might be prosecuted will be fined and won't pay which costs even more to follow up.
We should know that the legal system does not create an obedient society.
In a real like political misinformation, this will have the effect of making people trust non-watermarked images more, which will then be used by foreign actors to pass off propaganda as legitimate.
Also, if you don't hold people responsible for spreading an image they know is fake, bad actors can take advantage of this even within the US (they purposefully spread a image they have reason to think is fake but lacking a watermark), but holding people responsible for a strict liability crime for spreading AI without knowing it is AI seems an even worse route.
I'm not sure a law even makes the issue better in a 'don't let perfect be the enemy of good' sort of way.
Yes, software LPEs are a risk -- as they are in every nontrivial computer system. New ones will appear, and old ones will be closed in time, as TFA acknowledges.
Re hardware attacks: The (neat!) glitch injection attack the author describes in the linked "lighter" page only raises the implementation cost of doing image certification properly. For example, if the camera module presented only an interface that dumped raw RGB or JPEG-encoded data plus a digital signature that used a private key known only to the manufacturer, then all that would be required to verify a "downstream" image would be to keep a copy of those original bytes inside the final (potentially cropped, filtered, AI-ed, etc.) image, in the worst case roughly doubling its size on disk (though certainly more efficient schemes could be designed). Any interested third party could then compare the original and final images by eye and decide for themselves whether or not the subsequent processing materially changed the image's "meaning".
Finally: Does the existence of lock picks or bolt cutters render padlocks pointless today? Does it corrode society by encouraging people to mistakenly believe that anything they put behind a $5 padlock will be safe forever? No, and no.
Each of them weaponizing the rules of the platform that (for sensible reasons) demand you engage with the strongest interpretation of the message/argument you see.
The asymmetry of effort there is unsustainable, and that's exactly the point.
No idea how that could be solved. Maybe a meta comment like this one helps.
__
I mean if you think about it, it shouldn't be possible for some anon account to drop this and sound like it's a worthy contribution to a debate against some real person with a real name, a track record and multiple thousand dollars of bricked hardware leading up to that assessment. (Nor would it make sense for a non-anon but equally empty account)
It makes no sense, and the guarantees regarding protection of speech and all do not apply to these topics, because it's not an opinion that would get your real name in jail.
What can we do about these social exploits. Someone tell me please. It's driving me up the walls
All I can perceive in it is a generalised hate towards some broader thing that you feel certain I'm consciously aligned with somehow, and that you think is inherently and obviously evil. Because... I don't use my real name on here? (Is your real name "hypfer"?) Because I don't have bricked hardware to back up my opinions?
If you want to convince me or others that something I wrote is wrong, stop hyperventilating and engage with at least one of the specific claims in my post. For your own sake, I'd also suggest editing or outright deleting your original post.
What is interesting is what happens when these tactics are called out in a meta comment like I did, because it's actually a common thing that people start flailing like this once you side-step the script that was supposed to be followed.
Someone acting in good faith would not counter with an attack and a double-down like this, but with intent to resolve the situation (+ probably feeling a bit bad about an exchange having failed and being misunderstood).
I also like the "hyperventilating" claim. Easiest way to get out of a situation is to invalidate the source, and easiest way to do that is to claim emotions.
And the fake concern (for what, even?) of course.
> For your own sake, I'd also suggest editing or outright deleting your original post.
___
Anyway. I think the convincing people is actually working quite well here. Though not in the sense you'd think.
I'm just pointing a spotlight at what I believe is violating the spirit of the rules (while staying within the letter of the rules).
What other people make out of that is their decision to make.
Very bizarre.
I'm sorry man. The problem is that this exact described dynamic (see also the other reply by me which you seem to have conveniently missed), is that it affects _all_ internet spaces and makes them utterly miserable.
I agree though that this meta stuff doesn't exactly improve SNR, and I am open for better solutions. But those need to actually solve the problem, instead of just silencing the immune response.
___
Interesting side-thought
> with less karma too
I think this might point at (one of the) root cause(s) of the dysfunction I'm pointing at here.
Internet points ceased to be a metric documenting value quite a while ago. Something something Goodhart
At least I know that they understand my writing and that they can help me understand other writing I don't.
I can assure you that there is a point. Whether it is worth bothering is of course your decision. I'd wager probably not, but I guess that depends. No hard feelings either way.
(This is true in general: if you add a trust signal that is mainly just a bit of effort to broadcast, you'll find that scammers and fraudsters will show that signal much more reliably than honest actors. For example, every email spammer has DMARC and DKIM set up absolutely perfectly)
What do you think of my digital signature idea?
A padlock shouldn't be the only component of the bigger physical security picture.
A random person carrying/using bolt cutters or trying to pick a lock looks suspicious, and should be noticed by on-site staff or whoever is monitoring the security cameras.
If the padlock is decent, there will also be an inherent delay involved in bypassing it using those tools, which should increase the likelihood of the person being noticed.
If the padlock is used in an unattended/unmonitored location (i.e. a remote vacation house with no neighbours and no security cameras), then the padlock is probably only good for keeping honest people honest.
A lot of physical security => information security analogies are misleading for the same reason. In information security, it's very possible for an adversary to have effectively unlimited time to perform their attack (or to develop the means to perform the attack quickly).
Imagine a scenario where any determined person could e.g. spend a month in their home workshop and develop a pair of gloves containing transducers that would vibrate any padlock open in seconds. They could mimic the action of using the key or entering the combination to avoid looking suspicious. Also, the gloves have a button that instantly creates another pair of the same gloves at no cost. How much value would a padlock have in that scenario? That's the kind of asymmetric playing field one has to consider in information security contexts.
The problem is not identifying AI generated media
The problem is identifying real media. That it can actually do.
At over a decade old, still prescient as ever: https://www.youtube.com/watch?v=HUEvRyemKSg
RMS must be having daily nightmares at this point.
P.S.: Fantastic talk you linked there.
Doesn't sound like it's engineering-driven, even though they still do have a lot of capable engineers sitting there and atrophying.
I also wouldn't rule out that the less capable ones actually believed that the systems they've built are unrootable or something like that.
It seems like there's a big disconnect between what C2PA says it's for and what certain journalists think it's for.
However I question the value-add when e.g. the BBC website is already authenticated by nature of being served over HTTPS, and anyone who redistributes BBC content can and should link back to the source.
> It's always been obvious that one could point a camera at a screen, I don't think anyone involved with C2PA has claimed otherwise.
They haven't claimed otherwise exactly, but some have implied it's a solvable problem. Here's where the "learn more" link goes, for when Youtube annotates a video as having C2PA metadata: https://support.google.com/youtube/answer/15446725 (Google is a C2PA Steering Committee member)
> The metadata that leads to a 'Captured with a camera' disclosure is made by a third party (for example, a camera manufacturer). This means that there is some risk that someone could take a photo of another screen showing synthetic content. Because the other screen shows an image that has been modified, it wouldn't be eligible for the 'Captured with a camera' disclosure. This issue is called 'air-gapping'. Camera manufacturers will continue to develop detection measures to prevent 'air-gapping', but the sophistication of those detection measures may vary in the near term.
Interestingly they do not mention any of the other known limitations. Their phrasing is highly weasel-wordy, but the implication is clearly that they imagine picture-of-screen detection to become robust (somehow) in the medium-to-long term.
The value would be in images reposted to social media where the website an show a badge that says it came from a certain source.
I don't think completely solving this sort of problem is even possible.
The analog hole is alive and well:)
The idea that it could be used to attest the authenticity of any random person or device surely wasn't a thing serious people expected was it?
But that is also not the case, because whatever keys are in those devices may have been duplicated in the factory or somewhere along the supply chain. Or the stuff is cloud connected and an exploit can be executed via that.
Or, as written in the blog post you're commenting on, software exploits.
The whole idea is that the concept works for no one.
If there's no trust afforded to the device holder, or it's manufacturer, there's no trust in anything.
Always to degrees, and never fully, but trust can still be had.
Most people don't read HN, or understand tech, and so if the device says "captured with camera" then they will believe it since Google says it's true.
Accusing someone of a crime, with fake but verified photographic or video evidence will be trivial, and claiming it's fake just makes someone tap the "Google says it's true" sign.
It won't stop fraud by governments and/or determined/well-resourced attackers, but it'll make it difficult enough for 99.99% of the public. And as usage drops over time, it becomes more socially acceptable to justify further limitations.
Governments and corporations (e.g. banks) will require that you use a "trusted" (meaning locked-down) devices to interact with their services. We're already seeing some companies block GrapheneOS/LineageOS.
Hardware attestation stands unbroken to my knowledge, only software attestation can be faked, and even then it's a constant cat and mouse game which Google continues playing until they are done with Pixel 3 generation.
C2PA is not immune to the analogue hole, sure, but dark room + photo of a photo approach falls apart the moment you bake in depth data into the image, which is already done.
Android hardware attestation using root-based verification is highly insecure. It depends on the weakest links in the overall ecosystem. There are tons of leaked keys from insecure TEE implementations. People can often even downgrade to an ancient TEE implementation to exploit it when anti-rollback wasn't used for updates. Devices never updated since launch can be used to get keys via known vulnerabilities. Google doesn't revoke all the known leaked keys because it would break compatibility across many devices. Originally, private keys were provisioned to 100k or more devices in batches. They've moved to a system where each can get a unique key and then the ones used by apps are dynamically rotated but it's only the Pixel 7 and later using it in practice for Pixels and other devices took far longer to adopt it. That only got forced in the past year or so for other devices.
Android hardware attestation using pinning is highly secure on devices with a good implementation but that doesn't work for this use case. It could work for giving out phones to people and then verifying those are still genuine, not tampered with and have continued applying updates on an ongoing basis.
I have ordered a faulty Sony A7 IV motherboard, but due to its faulty-ness and the lack of the rest of the camera, I'm not sure how far I'll be able to get with it.
This was a technology that required international governmental prescription, not voluntary or viral adoption. Either way, it was horrifically flawed from the outset.
¹in a non-AI, traditional way, that doesn't mislead the viewer and this entire footnote should reveal how subjective and intractable this problem is
The point is not to prevent state-sponsored actors to produce fake media, but to add friction and avoid shady marketing agency and photographs from claiming their pictures are genuine.
If we're trying to decide whether a high profile politician has committed a crime, then yeah, C2PA on the footage isn't fully trustworthy. However, every bit of footage you get that corroborates the story raises the threshold of the attack.
If we're trying to decide whether Joe Everyman has crossed a double solid while driving his truck? C2PA is probably good enough. The chances of that footage being faked by a malicious party would be low even without C2PA, but C2PA makes them even lower.
And, given that the main threat here is disinformation by nation state actors, they can also attack the camera module (or its supply chain) instead.
When did that happen? I thought we were just talking about people being able to prove they took a photo, and it wasn't photoshopped after the fact.
And, Apple could choose to integrate a LiDAR depth map into the signed photo as a mitigation against the analog attacks (eg. pictures of screens).
The provenance “proof” these approaches provide is very tenuous and nowhere near the “this is a real photo of a real world event taken by a real camera and not an AI image” proof that marketing types like to push.
Apple doesn’t want a PR disaster where some crazy image is totally fake but becomes world news because it is “cryptographically signed as being from a real iPhone so it must be real!”
>Images captured with an opt-in Reference mode can be authenticated to confirm they were taken with an iPhone. Authenticating is done by tapping the Reference badge on the image, which sends the raw image, sensor signatures, capture time frame, and the unique hardware identifiers of the sensor to Apple's Private Cloud Compute (PCC) servers. PCC uses the information to determine whether the camera captured the photo, gives it a unique ID, and then returns an authenticated version to the user's device.
If it does ship like that, it’s hard to not imagine a situation as I described earlier - an “iPhone Reference Image” being used to propagate fake news, at which point the credibility of the feature goes to 0 (and Apple’s takes a severe hit).
Wait & see.
But:
- You cannot prove that no one has ever been able to break a Secure Enclave or a YubiKey or another secure element. That's okay, these companies focus on making it so expensive that it's not worth doing.
- The analog "attack vector" is real, but that was always true with analog cameras as well. Anyone could have taken an analog picture of a screen, or even painted a hyper realistic image of something that never happened.
I think a realistic goal for provenance is to at least get to parity with analog cameras ("this is a picture directly from a sensor"), not to make the perfect system for proving that a photo is of a real world event.